Showing posts with label linux security. Show all posts
Showing posts with label linux security. Show all posts

Wednesday, December 10, 2008

Kismet - a wireless sniffer and detector

You can't hide your wireless Access Point (AP) from kismet's eye. Kismet will discover every AP within range although with AP has hidden SSID.

Description from site:

What is Kismet

Kismet is an 802.11 layer2 wireless network detector, sniffer, and
intrusion detection system. Kismet will work with any wireless card which
supports raw monitoring (rfmon) mode, and can sniff 802.11b, 802.11a,
802.11n, and 802.11g traffic (devices and drivers permitting).

Kismet identifies networks by passively collecting packets and detecting
standard named networks, detecting (and given time, decloaking) hidden
networks, and inferring the presence of non-beaconing networks via data
traffic.






Feature Overview

Kismet has many features useful in different situations for monitoring
wireless networks:
- Ethereal/Tcpdump compatible data logging
- Airsnort compatible weak-iv packet logging
- Network IP range detection
- Built-in channel hopping and multicard split channel hopping
- Hidden network SSID decloaking
- Graphical mapping of networks
- Client/Server architecture allows multiple clients to view a single
Kismet server simultaneously
- Manufacturer and model identification of access points and clients
- Detection of known default access point configurations
- Runtime decoding of WEP packets for known networks
- Named pipe output for integration with other tools, such as a layer3 IDS
like Snort
- Multiplexing of multiple simultaneous capture sources on a single Kismet
instance
- Distributed remote drone sniffing
- XML output


Typical Uses

Common applications Kismet is useful for:
- Wardriving: Mobile detection of wireless networks, logging and mapping
of network location, WEP, etc.
- Site survey: Monitoring and graphing signal strength and location.
- Distributed IDS: Multiple Remote Drone sniffers distributed throughout
an installation monitored by a single server, possibly combined with a
layer3 IDS like Snort.
- Rogue AP Detection: Stationary or mobile sniffers to enforce site policy
against rogue access points.

check out the documentation and download here

Tuesday, October 14, 2008

Haxor

Komputer yang tidak dilindungi tembok api (firewall) rawan terkena serangan Haxor.

Istilah cracker atau hacker merupakan istilah yang sering kita dengar. Bagaimana denga haxor? Meski tidak sepopuler dua istilah sebelumnya, dampak perbuatan haxor kadang justru lebih merusak ketimbang cracker atau hacker. Haxor adalah sebutan untuk orang-orang yang memiliki kemampuan yang tinggi di bidang komputer dan gemar berbuat prank, alias usil melalui jaringan atau internet. Kesimpulannya, Tidak peduli firewall, siap-siap saja kehilangan data penting.

referensi:
PCmag

Artikel Terkait

Tuesday, June 24, 2008

Lubang Keamanan pada Firefox 3

Walapun firefox 3 sangat diperhatikan keamanannya, ternyata lubang keamanan ditemukan di web browser firefox 3. Tentu saja hal ini akan mempengaruhi 8 juta komputer yang telah men-download dan meng-install-nya. Berikut ini adalah berita yang saya kutip dari softpedia


Since the new release of popular web browser Mozilla Firefox 3.0, over 14 million downloads have been registered by the counter posted on the Spread Firefox website. But just in a few hours (about five) after the Mozilla Firefox 3.0 was made available to the public, security flaws have been reported.
TippingPoint, a provider of network-based intrusion prevention systems, was informed about existing security issues in Mozilla Firefox 3.0 through its program Zero Day Initiative (ZDI) that rewards security researchers for exclusive information disclosing vulnerabilities founded in software products.

Even the new security features of Firefox 3.0 have the main priority to maintain personal information safe and to protect users from phishing and malware, TippingPoint confirms the existence of a critical vulnerability of high severity that affects Mozilla Firefox 3.0 (ZDI ID: ZDI-CAN-349) and prior versions of Firefox 2.0.x: "We verified the vulnerability in our lab, acquired it from the researcher, then promptly reported the vulnerability to the Mozilla security team shortly after. Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code. Not unlike most browser based vulnerabilities that we see these days, user interaction is required such as clicking on a link in email or visiting a malicious web page."

In response to this security report, Mozilla Security Blog posted, "This issue is currently under investigation. To protect our users, the details of the issue will remain closed until a patch is made available. There is no public exploit, the details are private, and so the current risk to users".

If other security reports are taken into account, like the one found on SecurityFocus website which deals with an unspecified buffer overflow vulnerability (boundary condition error), the new security improvements from Firefox 3.0 are not powerful enough for present pishing and malware threats. In conclusion, having in mind that over 14 millions downloads of Mozilla Firefox 3.0 have been performed, users' computers are in potential danger until the security patches are released to fix the existing vulnerabilities.